Apache CloudStack 4.20.3.0/4.22.1.0 SAML Cert Validation Bypass (Forge Resp.)
CVE-2026-68745 Published on August 21, 2026
Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures.
Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.
Vulnerability Analysis
CVE-2026-68745 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Products Associated with CVE-2026-68745
Want to know whenever a new CVE is published for Apache CloudStack? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache CloudStack:- Version 4.5.2, <= 4.20.3.0 is affected.
- Version 4.21.0.0, <= 4.22.1.0 is affected.